Claude

IntuitionLabs is now a member of the Claude Partner Network – AI training and upskilling with Claude for pharma and biotech. Book a call.

IntuitionLabs

Zero Data Retention for Claude and Anthropic: A Life Sciences Deep Dive

zero data retentionclaudeanthropicai compliancedata privacyhipaa compliancebaaclaude enterpriseclaude coworklife sciences aigxp

Executive Summary

Claude's zero data retention story is defined less by a single toggle than by which of three distinct surfaces an organization is actually using. Claude Enterprise, the Anthropic API (the Claude Developer Platform), and Claude Cowork each carry their own BAA eligibility and their own retention mechanics, and none of the three inherits its posture automatically from the others. A policy that took effect June 9, 2026 adds a further wrinkle on top of that surface-level split: Anthropic now requires 30 days of retention for "Covered Models," currently Claude Mythos 5 and Claude Fable 5, even inside organizations that otherwise operate under a zero data retention agreement, applied identically on every platform where these models are offered, Anthropic's own API, AWS Bedrock, Google Cloud's Agent Platform, Microsoft 365, and Azure Foundry alike. What changes by infrastructure is not whether the 30-day window applies, it always does for these two models specifically, but which entity processes the retained data and how an admin configures it. Cowork, the newest of the three surfaces, carries the sharpest exclusion in this series: no configuration brings it under Anthropic's BAA at all. This guide walks through all three surfaces, the Covered Models policy and its actual scope, the console navigation paths a buyer would use to verify a given organization's settings, and closes with a Claude-specific version of this series' buyer checklist.

What Zero Data Retention Means

Zero data retention, as this series uses the term, is not one feature. It ranges from a self-serve API parameter to a sales-gated enterprise agreement to a contractual addendum, and it differs by platform and by which product tier a team actually uses. If you're arriving at this guide directly rather than from the first piece in this series, the short version is: naming this spectrum upfront prevents the common buyer mistake of assuming "does this vendor offer zero data retention" has a single yes-or-no answer. The full walk-through of that spectrum, and how it compares across ChatGPT, Copilot, Gemini, and Claude, lives in the series' opening guide.

Claude's version of this spectrum runs through product surface rather than a single account-level setting. Whether a given Claude interaction is retained depends on which surface carries it, Enterprise chat, the API via Claude Console, Claude Code, or Cowork, whether that specific workspace has zero data retention configured, and, as of June 9, 2026, whether the model in use is a Covered Model. A team that assumes one ZDR agreement or one signed BAA covers everything a person might touch inside "Claude" is working from a false assumption. The rest of this guide walks through why.

Three Surfaces, Three Different Postures

Claude Enterprise. Consumer-facing Team and Enterprise plans "already operate with standard retention" by default. ([1]) A Primary Owner can go further and activate HIPAA-ready configuration under Organization Settings, Data and Privacy, accepting Anthropic's Business Associate Agreement directly from that screen. ([2]) Absent that step, "standard Claude Enterprise plans do not include BAA coverage without action from a Primary Owner." ([2]) The BAA, once accepted, covers a defined list of Enterprise features, core chat, Projects, Artifacts, file creation and code execution excluding network access, voice, web search, research, and Skills, while explicitly excluding Claude Console, Claude Cowork, and beta features such as Claude in Office and Claude Design. ([2])

The Anthropic API, or Claude Developer Platform. This is the self-serve and sales-gated surface at once, depending on what a team is trying to do. Zero data retention here is "an agreement, not a dashboard toggle": Anthropic enables it per organization, through a sales conversation, after eligibility confirmation and a signed addendum. ([4]) Once granted, it applies to "eligible Anthropic APIs, Anthropic products that use your Commercial organization API key (including Claude Code accessed via the API), and Claude Code for Enterprise plans," and each new organization requires the agreement to be set up separately. ([4]) Anthropic's own developer documentation is specific about scope: ZDR covers the Messages and Token Counting APIs for eligible features, and Claude Code when used with a Commercial organization's API key or through Claude Enterprise with ZDR enabled. It does not cover the Claude Console itself, including its playground, Claude Managed Agents, Batch processing, the Files API, Claude for Excel, or the Claude Teams and Enterprise product interfaces, apart from the Claude Code exception just named. ([5]) A team that assumes a ZDR agreement blankets every feature it happens to call through the API is very likely wrong about at least one of them. For PHI specifically, a Primary Owner must sign a BAA and then "reach out to your Anthropic contact or our Sales team" to have HIPAA readiness turned on for the API organization. ([2])

Claude Cowork, the sharpest exclusion in this series. Anthropic's own BAA documentation is unambiguous: the agreement "excludes features such as Claude Console, Claude Cowork, or features currently in beta such as Claude in Office and Claude Design," and a companion article confirms "there's currently no configuration that allows BAA-covered access to Covered Models in Claude Code or Cowork." ([2][3]) Unlike some of the newer agentic surfaces covered elsewhere in this series, which carry partial or conditional BAA coverage, Cowork's exclusion has no ZDR-based escape hatch at all. It is available to enable, and administrators can turn it on for their organization from Organization Settings, Cowork, ([6]) but doing so does not, under any current configuration, bring the resulting workflows under the BAA. Cowork's own retention default is also more concrete than "standard" implies: session transcripts, whether running locally on a user's machine or in Anthropic's cloud, are retained for six years by default, the same span Anthropic applies to its Compliance API and Activity Feed records, unless an organization sets a shorter custom conversation-retention period under claude.ai's Organization Settings, Data and Privacy. ([5]) Worth stating plainly, since this guide itself runs inside Cowork: a life sciences buyer evaluating Cowork specifically should not assume that a signed BAA elsewhere in the organization extends to it, or that its default retention window is short.

SurfaceBAA-eligibleZDR-eligibleNotes
Claude Enterprise (core chat, Projects, Artifacts)Yes, with Primary Owner activationN/A, standard retention appliesCovered Models unaffected here since standard retention already applies
Claude Code (via 1P API or Enterprise OAuth)Only with ZDR enabledYes, qualified accountsDesktop remote mode and the web beta are excluded regardless of ZDR
Claude Developer Platform (API)Yes, for HIPAA-ready organizationsYes, per-organization agreementBatch API, Files API, Code Execution, and Computer Use are excluded from the BAA even when the org is otherwise eligible
Claude CoworkNo, in any configurationN/ANo ZDR-based exception exists

The BAA, Narrowly

IntuitionLabs already publishes a full feature-by-feature breakdown of Anthropic's BAA, alongside a cross-platform HIPAA comparison against ChatGPT, Copilot, and Gemini; that piece is the right place to go for the complete coverage table. This guide states only the one fact from that ground most load-bearing for a retention-focused reader, since it is the direct seam between the surface-level facts above and the Covered Models policy below: "Covered Models require 30-day data retention and aren't available with zero data retention (ZDR) enabled." ([2]) In practice, an organization cannot hold a standing ZDR agreement and use Claude Mythos 5 or Fable 5 under that same workspace. It has to choose, or maintain a separate workspace for each. For the full BAA table, see IntuitionLabs' existing guide.

The Covered Models Policy

What changed, in Anthropic's own words. Effective June 9, 2026, Anthropic requires limited retention on a defined class of models as part of its safety review process: "prompts submitted to, and outputs generated by, covered models are retained for 30 days to support our safety work, on every platform where these models are offered." ([1]) The policy applies to Claude Mythos 5, Claude Fable 5, and "future models with similar capabilities" that Anthropic designates as covered going forward. ([1])

Who this actually touches. It is narrower than "Claude retention just got worse for everyone," a characterization worth actively guarding against. Consumer plans, Free, Pro, and Max, are unaffected, "since we already retain inputs and outputs on these surfaces." ([1]) The policy "only applies to organizations that have set up workspaces with zero data retention (ZDR) in Claude Console, use Claude Code with ZDR in Claude Enterprise, or access Claude through AWS Bedrock, Google Cloud Agent Platform, or Microsoft Foundry with ZDR." For every other organization, "there is no change and there's nothing to configure." ([1])

Why Anthropic is doing this. Mythos 5 and Fable 5 "represent a substantial increase in model capabilities," some of which carry both benign and malicious uses, particularly in the cyber and bio domains. ([1]) Retention supports detecting patterns that only become visible across multiple requests, Anthropic names Best-of-N jailbreaking and larger campaigns such as state-sponsored misuse as examples, since these "only surface when our safeguards classifiers can zoom out across many requests" rather than evaluating one prompt at a time. ([1])

How the retained data is protected. "By default, no Anthropic personnel can read your retained conversations." Human review happens only through a controlled path, typically when automated trust and safety systems flag content, restricted to "a small set of approved reviewers," with every access instance recorded in "a tamper-proof log that reviewers cannot suppress or modify." After 30 days, deletion is automatic "except in the rare cases where it's been flagged... or we're legally required to keep it." Eligible organizations can additionally add customer-managed encryption keys and access transparency audit logs. ([1])

What an organization needs to configure, by access path. Directly through Claude Platform, a workspace administrator enables retention for the specific workspace that needs covered models, under Console, Settings, Workspaces, Privacy Controls; other ZDR-enabled workspaces in the same organization keep their existing zero-retention status untouched. ([1]) Through Claude Enterprise with ZDR, Anthropic states it is "releasing controls in the admin console so your Primary Owner can change the retention setting directly," and offers to help set up a separate sandbox organization for any team that would rather not touch its production org while testing. ([1]) Through Claude chat or Cowork under Enterprise, no action is needed at all, "these surfaces already operate with standard retention" regardless of the Covered Models policy, though as the Three Surfaces section above notes, Cowork's own "standard" default runs to six years, not a short window. ([1])

Same Policy, Five Infrastructures

A genuine cross-platform wrinkle worth a buyer's attention, and worth stating precisely rather than loosely: the 30-day Covered Models retention window is not a Google Cloud quirk, an AWS quirk, or a Microsoft quirk. Anthropic's own documentation is explicit that it applies "on every platform where these models are offered," identically, whether accessed through Anthropic's own Claude Platform, AWS Bedrock, Google Cloud's Agent Platform, Microsoft 365, or Azure Foundry. ([1]) What genuinely does vary across those five surfaces is not whether the retention applies, but two narrower things: which entity acts as the data processor for the retained content, and the specific mechanics an administrator uses to turn retention on.

Access pathWhere retained data is processedConfiguration mechanic
Anthropic's own Claude PlatformAnthropicPer-workspace toggle, Console, Settings, Workspaces, Privacy Controls
AWS BedrockAWSEnabled per Bedrock's own retention configuration; mechanics parallel the direct API
Google Cloud Agent PlatformGoogle CloudEnabled per Google Cloud's own Agent Platform documentation; retained data stays within GCP
Azure FoundryConfigured per Azure SubscriptionA separate Azure Subscription is required if the organization's primary subscription already has ZDR configured
Microsoft 365 (Copilot, Researcher, Copilot Studio)Anthropic, as an independent data processor, not a Microsoft subprocessorTenant admin opt-in under "Preview models with Data Retention," default-off regardless of region

The fifth row is worth naming on its own, since it is a genuinely distinct venue beyond the three Anthropic names directly in its own Covered Models article. Anthropic's mainline models run inside Microsoft Copilot, Researcher, Copilot Studio, Power Platform, and Copilot in Microsoft 365 apps as a Microsoft subprocessor, enabled by default for most commercial-cloud customers outside the EU, EFTA, and UK. ([10]) Mythos 5 and Fable 5 specifically sit outside that arrangement, carved out as "Preview models with Data Retention": for these, "Anthropic acts as an independent data processor, not a Microsoft subprocessor," their use is optional, and the toggle governing them is "default-off for all scenarios, including in regions when different Anthropic models are on by default." ([10]) The same two-tier shape, standard models under the host's own terms, Covered Models under Anthropic's own retention terms as a condition of use, recurs here for a fourth infrastructure provider, not only the three AWS, Google Cloud, and Azure Foundry surfaces named directly in Anthropic's own article.

One correction worth stating here rather than passing along unexamined: a sibling analysis in this series, covering Claude on Google Cloud specifically, frames the Fable 5 and Mythos 5 retention requirement as "imposed by Anthropic's own requirement as a condition of Google hosting these specific models." That is accurate as written, but read on its own could suggest the requirement is particular to Google Cloud. It is not. The retention window is the same 30 days, required by Anthropic, on every one of the five surfaces in the table above. The genuinely infrastructure-dependent facts are data locality and configuration mechanics, not the existence of the requirement itself. For the Google Cloud side of this same story, including the FedRAMP High note for Claude on Google Cloud's Agent Platform, see this series' Gemini and Vertex AI deep dive.

Console Navigation: Where Retention Controls Actually Live

Anthropic's own documentation names three specific paths, and this guide states them exactly rather than paraphrasing loosely, since a compliance reviewer verifying a vendor's claims needs the literal navigation, not a summary. Claude Console, Settings, Privacy, for the workspace-level retention toggle governing API usage. ([5]) Claude Console, Settings, Workspaces, Privacy Controls tab, the specific control Anthropic names in its own Covered Models article for turning on retention for a given workspace. ([1]) claude.ai, Organization Settings, Data and Privacy, the Enterprise admin path, also where a Primary Owner activates HIPAA-ready configuration and accepts the BAA. ([1][2]) For Cowork specifically, a separate and unrelated control: Organization Settings, Cowork, "Enable for your organization," a feature-enablement toggle rather than a retention setting, since Cowork carries standard retention regardless of this switch. ([6])

Consistent with this series' own verification standard, it is worth stating plainly that no screenshot of any of these three screens turned up anywhere in this guide's research, across an extensive, multi-pass search. The console pages themselves sit behind organization-level authentication and were not independently reachable during this guide's drafting. Per the standard this series has held itself to across every prior deep dive, a platform having no available screenshot for a given control does not shrink that section's analytical depth; the navigation paths above are independently confirmed against Anthropic's own current documentation, a text-verified equivalent rather than a substitute presented as something it is not.

Two genuinely adjacent, honestly-framed assets exist alongside that gap, carried forward from this series' original sourcing. Anthropic's own blog post on new admin visibility and spend controls includes a real screenshot of the Claude Analytics admin dashboard, usage and spend broken down by team and user, not a privacy or retention screen, but genuine first-party admin-console material. ([11])

Claude Analytics admin dashboard showing usage and spend broken down by team and user The Claude Analytics admin dashboard, showing usage and spend broken down by team and user (not a privacy or retention screen itself, included here as genuinely adjacent admin-console material). Screenshot source: Anthropic, "Giving admins more visibility and control over Claude usage and spend."[11]

Separately, a third-party SSO setup guide shows the actual claude.ai sign-in page with a visible "Continue with SSO" option, again adjacent rather than a retention control itself. ([12])

The claude.ai sign-in page showing a Continue with SSO option The actual claude.ai sign-in screen, showing the "Continue with SSO" option (not the retention settings screen itself, included here as genuinely adjacent admin-relevant material). Screenshot source: T-Minus365, "How to Set Up Claude SSO with Microsoft Entra ID."[12]

For the CLI angle, two community-recorded Claude Code terminal sessions on asciinema show real usage of the tool in practice. ([13][14])

Claude Code CLI terminal session mid-task, saving a file via an MCP-driven keystroke tool A still from a community-recorded Claude Code terminal session, captured mid-task rather than at the loading screen: Claude Code sends keystrokes through an MCP game-controller tool to write and save a file in the nano editor, visible tool calls and terminal state included. Screenshot source: asciinema recording.[13]

Claude Code CLI terminal session using the NotebookLM skill to create a notebook and add research sources A still from a second community-recorded Claude Code terminal session, showing the NotebookLM skill actively creating a notebook, running deep web research, and adding documentation sources, a genuine, on-topic session that resolves this series' earlier "found via search only" verification flag on this source. Screenshot source: asciinema recording.[14]

Certifications and the Trust Center

Anthropic holds a defined set of compliance credentials: HIPAA-ready configuration with a BAA available, SOC 2 Type I and Type II, ISO 27001:2022 for information security management, and ISO/IEC 42001:2023 for AI management systems, achieved in January 2025, among the first frontier AI labs to do so. ([7]) Anthropic's own Covered Models article points readers to "the corresponding technical white paper" on the threat model for retained data and its associated privacy controls, hosted directly on the Trust Center. ([1]) Worth naming precisely, since it is the primary artifact a compliance reviewer would actually request in a vendor assessment: the paper is titled "Security and Privacy Design of Anthropic Data Retention and Review." ([9]) The Trust Center itself, described in its own site metadata as the place to "find our compliance artifacts, request documentation, and view high-level details on controls we adhere to," is the broader hub for these materials. ([8]) No public screenshot of the Trust Center's interior exists in this guide's sourcing; it is treated here as a documentation pointer, not a visual asset.

Claude in Microsoft 365 Copilot

Every deep dive in this series has had to state honestly where its visual evidence runs thin, and Claude's own console has been the hardest of the four platforms to source a genuine retention-screen screenshot for. What this guide's research did find, in a surface adjacent to Anthropic's own but still directly on point, is two real, current, first-party screenshots inside Microsoft's own admin documentation for the Anthropic subprocessor arrangement described above.

The first shows the actual Microsoft 365 admin center screen an IT administrator uses to enable or restrict Anthropic as an AI provider tenant-wide, captioned directly by Microsoft as "the choice in the Microsoft 365 admin center UI to use Anthropic models." ([10]) It is a genuine screenshot of Claude named explicitly inside a live enterprise admin panel, comparable in kind to the console assets this series has been able to source for other platforms.

Screenshot of the choice in the Microsoft 365 admin center UI to use Anthropic models The Microsoft 365 admin center screen used to enable or restrict Anthropic as an AI provider for the tenant. Screenshot source: Microsoft Learn, "Anthropic models in Microsoft Online Services."[10]

The second is, functionally, the closest thing this entire series has found anywhere to a real screenshot of a Covered Models retention control: Microsoft's own "AI models preview page" screenshot, showing the specific opt-in toggle that governs Fable 5 and Mythos 5 availability inside a Microsoft 365 tenant, labeled in the product itself as "Preview models with Data Retention." ([10]) It should be framed honestly rather than oversold: this is Microsoft's admin surface, not Anthropic's own console, and the control it shows governs whether the Preview models are available to the tenant at all, not a granular per-conversation retention setting. But it is real, current, and names the exact policy this guide's Covered Models section describes, which is more than any other console screenshot found anywhere in this series' Claude-specific sourcing to date.

Screenshot of the AI models preview page showing the Preview models with Data Retention toggle Microsoft's "AI models preview page," showing the opt-in toggle for Preview models with Data Retention, the specific control governing Claude Fable 5 and Mythos 5 availability in a Microsoft 365 tenant (Microsoft's admin surface, not Anthropic's own console; the tenant-level control closest to a genuine Covered Models retention screenshot found anywhere in this series' Claude sourcing). Screenshot source: Microsoft Learn, "Anthropic models in Microsoft Online Services."[10]

What to Ask Before You Sign

QuestionWhy it matters
Which of the three surfaces does your team actually use, Enterprise, the API, or Cowork?BAA and ZDR eligibility differ by surface, not by brand
If PHI will touch this workflow, has your Primary Owner activated HIPAA-ready configuration and accepted the BAA?Standard Enterprise plans carry no BAA coverage without that explicit step
Does your use case require Claude Mythos 5 or Fable 5?Covered Models require 30-day retention and cannot run under a standing ZDR agreement in the same workspace
If you access Claude through a cloud intermediary, AWS, Google Cloud, Microsoft 365, or Azure, do you know which entity is the data processor for the specific model version in use?The retention window is uniform, but the processor and configuration mechanics differ by infrastructure
Is Claude Cowork in scope for this workflow?No configuration currently brings Cowork under the BAA, regardless of ZDR status elsewhere in the organization

For the fuller platform-by-platform HIPAA comparison behind the second question, see IntuitionLabs' existing guide. For the general version of this checklist across all four major platforms, see the series' opening guide.

What's Next in This Series

This is one of four platform-specific deep dives in IntuitionLabs' zero data retention series, alongside the pillar's four-platform overview. The four deep dives are complementary, not sequential, and can be read in any order: the series' opening guide, the ChatGPT and OpenAI API deep dive, the Copilot and Azure OpenAI deep dive, and the Gemini and Vertex AI deep dive. Readers evaluating an AI vendor specifically for a validated GxP environment should also read IntuitionLabs' existing platform-by-platform HIPAA comparison, which covers ground this guide deliberately does not repeat.

Every platform claim in this guide traces to Anthropic's own current Help Center, Privacy Center, or Trust Center documentation, rather than third-party summaries where a primary source was available, and one framing from this series' own Gemini and Vertex AI deep dive was corrected above rather than passed along unexamined, since the 30-day Covered Models retention window applies uniformly across every platform where these models are offered, not as a Google-specific term. One disclosure is worth stating plainly since Claude is the platform under direct review in this piece: IntuitionLabs is a member of the Claude Partner Network. This guide's claims about Claude's own terms were held to the same sourcing standard applied to the other three platforms in this series, and no other vendor relationship with Anthropic informed them.

Adrien Laurent

Need Expert Guidance on This Topic?

Talk to IntuitionLabs about how to evaluate Claude and Anthropic on data retention and privacy terms for your regulated environment.

I'm Adrien Laurent, Founder & CEO of IntuitionLabs. With 25+ years of experience in enterprise software development, I specialize in creating custom AI solutions for the pharmaceutical and life science industries.

Book a Free Strategy Call

DISCLAIMER

The information contained in this document is provided for educational and informational purposes only. We make no representations or warranties of any kind, express or implied, about the completeness, accuracy, reliability, suitability, or availability of the information contained herein. Any reliance you place on such information is strictly at your own risk. This document may contain content generated with the assistance of artificial intelligence technologies. AI-generated content may contain errors, omissions, or inaccuracies. Readers are advised to independently verify any critical information before acting upon it. All product names, logos, brands, trademarks, and registered trademarks mentioned in this document are the property of their respective owners.


External Sources (14)[1]https://support.claude.com/en/articles/15425996-data-retention-practices-for-covered-models

[2]https://privacy.claude.com/en/articles/8114513-business-associate-agreements-baa-for-commercial-customers

[3]https://support.claude.com/en/articles/15455031-covered-models-under-a-business-associate-agreement-baa

[4]https://privacy.claude.com/en/articles/8956058-i-have-a-zero-data-retention-agreement-with-anthropic-what-products-does-it-apply-to

[5]https://platform.claude.com/docs/en/manage-claude/api-and-data-retention

[6]https://support.claude.com/en/articles/13455879-use-claude-cowork-on-team-and-enterprise-plans

[7]https://privacy.claude.com/en/articles/10015870-what-certifications-has-anthropic-obtained

[8]https://trust.anthropic.com/

[9]https://trust.anthropic.com/resources?s=7ksqkied5hn0pocsj206m&name=[anthropic]-security-and-privacy-design-of-anthropic-data-retention-and-review

[10]https://learn.microsoft.com/en-us/microsoft-365/copilot/connect-to-ai-subprocessor

[11]https://claude.com/blog/giving-admins-more-visibility-and-control-over-claude-usage-and-spend

[12]https://tminus365.com/how-to-set-up-claude-sso-with-microsoft-entra-id-10-minute-guide/

[13]https://asciinema.org/a/732644

[14]https://asciinema.org/a/767284

Adrien Laurent

Need Expert Guidance on This Topic?

Talk to IntuitionLabs about how to put this guide into practice on your team.

I'm Adrien Laurent, Founder & CEO of IntuitionLabs. With 25+ years of experience in enterprise software development, I specialize in creating custom AI solutions for the pharmaceutical and life science industries.

DISCLAIMER

The information contained in this document is provided for educational and informational purposes only. We make no representations or warranties of any kind, express or implied, about the completeness, accuracy, reliability, suitability, or availability of the information contained herein. Any reliance you place on such information is strictly at your own risk. This document may contain content generated with the assistance of artificial intelligence technologies. AI-generated content may contain errors, omissions, or inaccuracies. Readers are advised to independently verify any critical information before acting upon it. All product names, logos, brands, trademarks, and registered trademarks mentioned in this document are the property of their respective owners.

© 2026 IntuitionLabs. All rights reserved.